remoteagent.online Privacy Policy
Last updated: August 2026
1. Introduction
remoteagent.online ("we", "our", "us") is committed to protecting your privacy and ensuring the security of your data. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the Agent Control Center at remoteagent.online.
We are based in the European Union and comply with the General Data Protection Regulation (GDPR), the EU AI Act, and applicable national data protection laws.
2. Data We Collect
2.1 Account Data
When you register, we collect your email address, username, and any profile information you voluntarily provide (name, avatar, bio, timezone).
2.2 Agent Configuration Data
Agent names, system prompts, tool definitions, model selections, and deployment settings you configure through the platform.
2.3 Usage and Telemetry Data
Agent call logs, latency metrics, token consumption, error rates, and audit trail entries. API key values themselves are encrypted and never stored in plaintext.
2.4 Technical Data
IP addresses, browser type and version, operating system, session timestamps, and referring URLs. This data is used for security monitoring and service improvement.
3. Data We Do NOT Collect
- Your LLM provider API keys (stored encrypted in your vault or managed client-side)
- End-user prompts processed through your agents (unless audit logging is explicitly enabled by you)
- Content of data processed through self-hosted instances (it never leaves your infrastructure)
- Payment card details (processed by our PCI-compliant payment partners)
4. Legal Basis for Processing (GDPR)
We process your data under the following legal bases:
- Contract Performance: To provide the Agent Control Center service you signed up for
- Legitimate Interest: Security monitoring, fraud prevention, service improvement
- Consent: Marketing communications (you may withdraw at any time)
- Legal Obligation: Compliance with applicable laws and regulatory requirements
5. How We Use Your Data
- To provide, maintain, and improve the Agent Control Center platform
- To authenticate your access and secure your account against unauthorized use
- To generate your agent performance analytics and audit reports
- To communicate service updates, security alerts, and billing information
- To detect, prevent, and investigate security incidents and platform abuse
- To comply with legal obligations and respond to lawful requests
6. Data Storage and Security
All data is encrypted at rest using AES-256 and in transit using TLS 1.3 with mutual TLS (mTLS) where applicable. Our infrastructure is hosted in the European Union. Self-hosted customers retain full control over their data storage and encryption.
We implement the following security measures:
- Regular security audits and penetration testing
- Strict access controls and multi-factor authentication for all staff
- Automated intrusion detection and 24/7 monitoring
- Immutable hash-chained audit logs for all administrative actions
7. Data Retention
We retain your data for as long as your account is active. Upon account deletion:
- Personal data is deleted within 30 days
- Anonymized usage statistics may be retained for service improvement
- Audit logs required for legal compliance are retained per statutory requirements
- Backups are purged according to our 90-day retention cycle
8. Your Rights (GDPR)
Under the GDPR, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interest
- Right to Withdraw Consent: Withdraw consent at any time
To exercise any of these rights, contact us at ai@mona.expert. We will respond within 30 days.
9. Third-Party Services and Subprocessors
We do not sell your personal data. We may use the following categories of subprocessors:
- Infrastructure: Cloud hosting, CDN, and database providers (all EU-based or GDPR-compliant)
- Communications: Email delivery services for transactional messages
- Payments: PCI-compliant payment processors
- Analytics: Self-hosted or privacy-respecting analytics (no third-party trackers)
A current list of subprocessors is available on request.
10. International Data Transfers
Where data transfers outside the EU are necessary, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions.
11. Cookies and Tracking
We use:
- Essential Cookies: Required for session management, authentication, and security. These cannot be disabled.
- Preference Cookies: Remember your theme, language, and display preferences.
- Analytics Cookies: Optional. We respect Do Not Track (DNT) browser settings.
No third-party advertising cookies or trackers are used on our platform.
12. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us immediately.
13. Changes to This Policy
We will notify you of material changes via email or platform notification. The "Last updated" date at the top of this page reflects the most recent revision.
14. Contact and Supervisory Authority
Data Controller: remoteagent.online
📧 ai@mona.expert
You have the right to lodge a complaint with your local data protection supervisory authority.
Österreichische Datenschutzbehörde
Barichgasse 40-42, 1030 Wien, Austria
www.dsb.gv.at